A recent variant of the TrickBot malware has transitioned from using traditional HTTP command-and-control (C2) methods to employing DNS tunneling. This new technique disguises data exfiltrated by the malware as standard DNS queries. Researchers from Fortinet's FortiGuard Labs highlighted that this modular TrickBot version uses encrypted commands interspersed within DNS packets, circumventing detection methodologies.
The malware features a persistent presence on infected systems through scheduled tasks and shows advanced capabilities such as injecting malicious code into processes. Despite past takedowns, the adaptability of TrickBot's operators demonstrates its continued threat in the cybersecurity landscape.